离线安装
离线安装几乎与在线安装相同,不同之处是您必须创建一个本地仓库来托管 Docker 镜像。本教程演示了如何在离线环境中将 KubeSphere 安装到 Kubernetes 上。
开始下方步骤之前,请先参阅准备工作。
步骤 1:准备一个私有镜像仓库
您可以使用 Harbor 或者其他任意私有镜像仓库。本教程以 Docker 仓库作为示例,并使用自签名证书(如果您有自己的私有镜像仓库,可以跳过这一步)。
使用自签名证书
-
执行以下命令生成您自己的证书:
mkdir -p certs
openssl req \ -newkey rsa:4096 -nodes -sha256 -keyout certs/domain.key \ -x509 -days 36500 -out certs/domain.crt
-
当您生成自己的证书时,请确保在字段
Common Name
中指定一个域名。例如,本示例中该字段被指定为dockerhub.kubekey.local
。
启动 Docker 仓库
执行以下命令启动 Docker 仓库:
docker run -d \
--restart=always \
--name registry \
-v "$(pwd)"/certs:/certs \
-v /mnt/registry:/var/lib/registry \
-e REGISTRY_HTTP_ADDR=0.0.0.0:443 \
-e REGISTRY_HTTP_TLS_CERTIFICATE=/certs/domain.crt \
-e REGISTRY_HTTP_TLS_KEY=/certs/domain.key \
-p 443:443 \
registry:2
备注
Docker 使用 /var/lib/docker
作为默认路径来存储所有 Docker 相关文件(包括镜像)。建议您添加附加存储卷,分别给 /var/lib/docker
和 /mnt/registry
挂载至少 100G。请参见 fdisk 的参考命令。
配置仓库
-
在
/etc/hosts
中添加一个条目,将主机名(即仓库域名;在本示例中是dockerhub.kubekey.local
)映射到您机器的私有 IP 地址,如下所示。# docker registry 192.168.0.2 dockerhub.kubekey.local
-
执行以下命令,复制证书到指定目录,并使 Docker 信任该证书。
mkdir -p /etc/docker/certs.d/dockerhub.kubekey.local
cp certs/domain.crt /etc/docker/certs.d/dockerhub.kubekey.local/ca.crt
备注
证书的路径与域名相关联。当您复制路径时,如果与上面设置的路径不同,请使用实际域名。
-
要验证私有仓库是否有效,您可以先复制一个镜像到您的本地机器,然后使用
docker push
和docker pull
来测试。
步骤 2:准备安装镜像
当您在离线环境中安装 KubeSphere 时,需要事先准备一个包含所有必需镜像的镜像包。
-
使用以下命令从能够访问互联网的机器上下载镜像清单文件
images-list.txt
:curl -L -O https://github.com/kubesphere/ks-installer/releases/download/v3.4.1/images-list.txt
备注
该文件根据不同的模块列出了
##+modulename
下的镜像。您可以按照相同的规则把自己的镜像添加到这个文件中。若需要查看完整文件,请参见附录。 -
下载
offline-installation-tool.sh
。curl -L -O https://github.com/kubesphere/ks-installer/releases/download/v3.4.1/offline-installation-tool.sh
-
使
.sh
文件可执行。chmod +x offline-installation-tool.sh
-
您可以执行命令
./offline-installation-tool.sh -h
来查看如何使用脚本:root@master:/home/ubuntu# ./offline-installation-tool.sh -h Usage: ./offline-installation-tool.sh [-l IMAGES-LIST] [-d IMAGES-DIR] [-r PRIVATE-REGISTRY] [-v KUBERNETES-VERSION ] Description: -b : save kubernetes' binaries. -d IMAGES-DIR : the dir of files (tar.gz) which generated by `docker save`. default: ./kubesphere-images -l IMAGES-LIST : text file with list of images. -r PRIVATE-REGISTRY : target private registry:port. -s : save model will be applied. Pull the images in the IMAGES-LIST and save images as a tar.gz file. -v KUBERNETES-VERSION : download kubernetes' binaries. default: v1.17.9 -h : usage message
-
在
offline-installation-tool.sh
中拉取镜像。./offline-installation-tool.sh -s -l images-list.txt -d ./kubesphere-images
备注
您可以根据需要选择拉取的镜像。例如,如果已经有一个 Kubernetes 集群了,您可以在
images-list.text
中删除##k8s-images
和在它下面的相关镜像。
步骤 3:推送镜像至私有仓库
将打包的镜像文件传输至您的本地机器,并运行以下命令把它推送至仓库。
./offline-installation-tool.sh -l images-list.txt -d ./kubesphere-images -r dockerhub.kubekey.local
备注
命令中的域名是 dockerhub.kubekey.local
。请确保使用您自己仓库的地址。
步骤 4:下载部署文件
与在现有 Kubernetes 集群上在线安装 KubeSphere 相似,您也需要事先下载 cluster-configuration.yaml
和 kubesphere-installer.yaml
。
-
执行以下命令下载这两个文件,并将它们传输至您充当任务机的机器,用于安装。
curl -L -O https://github.com/kubesphere/ks-installer/releases/download/v3.4.1/cluster-configuration.yaml curl -L -O https://github.com/kubesphere/ks-installer/releases/download/v3.4.1/kubesphere-installer.yaml
-
编辑
cluster-configuration.yaml
添加您的私有镜像仓库。例如,本教程中的仓库地址是dockerhub.kubekey.local
,将它用作.spec.local_registry
的值,如下所示:spec: persistence: storageClass: "" authentication: jwtSecret: "" local_registry: dockerhub.kubekey.local # Add this line manually; make sure you use your own registry address.
备注
您可以在该 YAML 文件中启用可插拔组件,体验 KubeSphere 的更多功能。有关详情,请参考启用可插拔组件。
-
编辑完成后保存
cluster-configuration.yaml
。使用以下命令将ks-installer
替换为您自己仓库的地址。sed -i "s#^\s*image: kubesphere.*/ks-installer:.*# image: dockerhub.kubekey.local/kubesphere/ks-installer:v3.4.0#" kubesphere-installer.yaml
警告
命令中的仓库地址是
dockerhub.kubekey.local
。请确保使用您自己仓库的地址。
步骤 5:开始安装
确定完成上面所有步骤后,您可以执行以下命令。
kubectl apply -f kubesphere-installer.yaml
kubectl apply -f cluster-configuration.yaml
步骤 6:验证安装
安装完成后,您会看到以下内容:
admin
Hangzhou@2024.
#####################################################
### Welcome to KubeSphere! ###
#####################################################
Console: http://192.168.0.2:30880
Account: admin
Password: P@88w0rd
NOTES:
1. After logging into the console, please check the
monitoring status of service components in
the "Cluster Management". If any service is not
ready, please wait patiently until all components
are ready.
2. Please modify the default password after login.
#####################################################
https://kubesphere.io 20xx-xx-xx xx:xx:xx
#####################################################
现在,您可以通过 http://{IP}:30880
使用默认帐户和密码 admin/P@88w0rd
访问 KubeSphere 的 Web 控制台。
备注
要访问控制台,请确保在您的安全组中打开端口 30880。
附录
KubeSphere 3.4 镜像清单
##kubesphere-images
registry.cn-beijing.aliyuncs.com/kubesphereio/ks-installer:v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/ks-apiserver:v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/ks-console:v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/ks-controller-manager:v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/kubectl:v1.20.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kubefed:v0.8.1
registry.cn-beijing.aliyuncs.com/kubesphereio/tower:v0.2.1
registry.cn-beijing.aliyuncs.com/kubesphereio/minio:RELEASE.2019-08-07T01-59-21Z
registry.cn-beijing.aliyuncs.com/kubesphereio/mc:RELEASE.2019-08-07T23-14-43Z
registry.cn-beijing.aliyuncs.com/kubesphereio/snapshot-controller:v4.0.0
registry.cn-beijing.aliyuncs.com/kubesphereio/nginx-ingress-controller:v1.3.1
registry.cn-beijing.aliyuncs.com/kubesphereio/defaultbackend-amd64:1.4
registry.cn-beijing.aliyuncs.com/kubesphereio/metrics-server:v0.4.2
registry.cn-beijing.aliyuncs.com/kubesphereio/redis:5.0.14-alpine
registry.cn-beijing.aliyuncs.com/kubesphereio/haproxy:2.0.25-alpine
registry.cn-beijing.aliyuncs.com/kubesphereio/alpine:3.14
registry.cn-beijing.aliyuncs.com/kubesphereio/openldap:1.3.0
registry.cn-beijing.aliyuncs.com/kubesphereio/netshoot:v1.0
##kubeedge-images
registry.cn-beijing.aliyuncs.com/kubesphereio/cloudcore:v1.13.0
registry.cn-beijing.aliyuncs.com/kubesphereio/iptables-manager:v1.13.0
registry.cn-beijing.aliyuncs.com/kubesphereio/edgeservice:v0.3.0
##gatekeeper-images
registry.cn-beijing.aliyuncs.com/kubesphereio/gatekeeper:v3.5.2
##openpitrix-images
registry.cn-beijing.aliyuncs.com/kubesphereio/openpitrix-jobs:v3.3.2
##kubesphere-devops-images
registry.cn-beijing.aliyuncs.com/kubesphereio/devops-apiserver:ks-v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/devops-controller:ks-v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/devops-tools:ks-v3.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/ks-jenkins:v3.4.0-2.319.3-1
registry.cn-beijing.aliyuncs.com/kubesphereio/inbound-agent:4.10-2
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-base:v3.2.2
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-nodejs:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-maven:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-maven:v3.2.1-jdk11
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-python:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.16
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.17
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.18
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-base:v3.2.2-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-nodejs:v3.2.0-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-maven:v3.2.0-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-maven:v3.2.1-jdk11-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-python:v3.2.0-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.0-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.16-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.17-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/builder-go:v3.2.2-1.18-podman
registry.cn-beijing.aliyuncs.com/kubesphereio/s2ioperator:v3.2.1
registry.cn-beijing.aliyuncs.com/kubesphereio/s2irun:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/s2i-binary:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/tomcat85-java11-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/tomcat85-java11-runtime:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/tomcat85-java8-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/tomcat85-java8-runtime:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/java-11-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/java-8-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/java-8-runtime:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/java-11-runtime:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/nodejs-8-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/nodejs-6-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/nodejs-4-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/python-36-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/python-35-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/python-34-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/python-27-centos7:v3.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/argocd:v2.3.3
registry.cn-beijing.aliyuncs.com/kubesphereio/argocd-applicationset:v0.4.1
registry.cn-beijing.aliyuncs.com/kubesphereio/dex:v2.30.2
registry.cn-beijing.aliyuncs.com/kubesphereio/redis:6.2.6-alpine
##kubesphere-monitoring-images
registry.cn-beijing.aliyuncs.com/kubesphereio/configmap-reload:v0.7.1
registry.cn-beijing.aliyuncs.com/kubesphereio/prometheus:v2.39.1
registry.cn-beijing.aliyuncs.com/kubesphereio/prometheus-config-reloader:v0.55.1
registry.cn-beijing.aliyuncs.com/kubesphereio/prometheus-operator:v0.55.1
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-rbac-proxy:v0.11.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-state-metrics:v2.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/node-exporter:v1.3.1
registry.cn-beijing.aliyuncs.com/kubesphereio/alertmanager:v0.23.0
registry.cn-beijing.aliyuncs.com/kubesphereio/thanos:v0.31.0
registry.cn-beijing.aliyuncs.com/kubesphereio/grafana:8.3.3
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-rbac-proxy:v0.11.0
registry.cn-beijing.aliyuncs.com/kubesphereio/notification-manager-operator:v2.3.0
registry.cn-beijing.aliyuncs.com/kubesphereio/notification-manager:v2.3.0
registry.cn-beijing.aliyuncs.com/kubesphereio/notification-tenant-sidecar:v3.2.0
##kubesphere-logging-images
registry.cn-beijing.aliyuncs.com/kubesphereio/elasticsearch-curator:v5.7.6
registry.cn-beijing.aliyuncs.com/kubesphereio/opensearch-curator:v0.0.5
registry.cn-beijing.aliyuncs.com/kubesphereio/elasticsearch-oss:6.8.22
registry.cn-beijing.aliyuncs.com/kubesphereio/opensearch:2.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/opensearch-dashboards:2.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/fluentbit-operator:v0.14.0
registry.cn-beijing.aliyuncs.com/kubesphereio/docker:19.03
registry.cn-beijing.aliyuncs.com/kubesphereio/fluent-bit:v1.9.4
registry.cn-beijing.aliyuncs.com/kubesphereio/log-sidecar-injector:v1.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/filebeat:6.7.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-events-operator:v0.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-events-exporter:v0.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-events-ruler:v0.6.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-auditing-operator:v0.2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/kube-auditing-webhook:v0.2.0
##istio-images
registry.cn-beijing.aliyuncs.com/kubesphereio/pilot:1.14.6
registry.cn-beijing.aliyuncs.com/kubesphereio/proxyv2:1.14.6
registry.cn-beijing.aliyuncs.com/kubesphereio/jaeger-operator:1.29
registry.cn-beijing.aliyuncs.com/kubesphereio/jaeger-agent:1.29
registry.cn-beijing.aliyuncs.com/kubesphereio/jaeger-collector:1.29
registry.cn-beijing.aliyuncs.com/kubesphereio/jaeger-query:1.29
registry.cn-beijing.aliyuncs.com/kubesphereio/jaeger-es-index-cleaner:1.29
registry.cn-beijing.aliyuncs.com/kubesphereio/kiali-operator:v1.50.1
registry.cn-beijing.aliyuncs.com/kubesphereio/kiali:v1.50
##example-images
registry.cn-beijing.aliyuncs.com/kubesphereio/busybox:1.31.1
registry.cn-beijing.aliyuncs.com/kubesphereio/nginx:1.14-alpine
registry.cn-beijing.aliyuncs.com/kubesphereio/wget:1.0
registry.cn-beijing.aliyuncs.com/kubesphereio/hello:plain-text
registry.cn-beijing.aliyuncs.com/kubesphereio/wordpress:4.8-apache
registry.cn-beijing.aliyuncs.com/kubesphereio/hpa-example:latest
registry.cn-beijing.aliyuncs.com/kubesphereio/fluentd:v1.4.2-2.0
registry.cn-beijing.aliyuncs.com/kubesphereio/perl:latest
registry.cn-beijing.aliyuncs.com/kubesphereio/examples-bookinfo-productpage-v1:1.16.2
registry.cn-beijing.aliyuncs.com/kubesphereio/examples-bookinfo-reviews-v1:1.16.2
registry.cn-beijing.aliyuncs.com/kubesphereio/examples-bookinfo-reviews-v2:1.16.2
registry.cn-beijing.aliyuncs.com/kubesphereio/examples-bookinfo-details-v1:1.16.2
registry.cn-beijing.aliyuncs.com/kubesphereio/examples-bookinfo-ratings-v1:1.16.3
##weave-scope-images
registry.cn-beijing.aliyuncs.com/kubesphereio/scope:1.13.0
反馈